Web/API pentesting
Web and API penetration testing for businesses
Human-led testing of authentication, authorization and business logic. Agree on scope and get evidence your team can act on.
What we test
REKON evaluates web applications and APIs through human judgment and supporting tools. Scope starts with business-critical flows: account access, cross-customer data, privileged operations and transactions. Request scope and a proposal.
Web applications: sessions and workflows
We examine authentication, account recovery, sessions, access controls and input handling within scope. For a B2B portal, we compare a user, an administrator and a user from another organization. Hiding a button is insufficient: the server must reject unauthorized actions.
APIs: objects, functions and state
We test APIs directly using authorized accounts and test data. We compare object-level and function-level access, tenant isolation and business state transitions. Endpoint count alone does not determine effort: roles, integrations and states matter too. OWASP distinguishes object-level authorization from function-level authorization.
Preparation, limitations and authorization
We agree on domains and APIs, version, environment, roles, contacts and testing window. Staging may be appropriate when it represents the relevant controls; production requires specific authorization and conditions. Denial of service, social engineering, internal infrastructure and third-party services are excluded unless explicitly agreed. Tests blocked by missing access are recorded as limitations, not validated controls.
Reporting, remediation and retesting
The deliverable describes scope, validated findings, evidence, impact and remediation. Retesting checks specific fixes under agreed conditions; it is not a new pentest and does not cover unrelated changes. Inspect the synthetic report and compare scoping variables.
Straight answers
How do I request a proposal?
- Share the application type, roles and objective through the contact form. Do not send credentials or customer data.
Does a pentest guarantee security?
- No. It evaluates an agreed scope and version within a testing window. Limitations and residual risk remain.
What is agreed before testing?
- Assets, permissions, environments, exclusions, communication, deliverables and retest terms.
Time to test your doors?
Tell us what needs validating. We answer with proposed scope, not a brochure.